# Using multiple hosts in env var / Elasticsearch filter

**URL:** <https://discuss.elastic.co/t/using-multiple-hosts-in-env-var-elasticsearch-filter/285090>\
**Category:** Logstash\
**Created:** [September 24, 2021, 2:32pm UTC](https://discuss.elastic.co/t/using-multiple-hosts-in-env-var-elasticsearch-filter/285090 "2021-09-24T14:32:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![whatgeorgemade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whatgeorgemade/32/103246_2.png) [@whatgeorgemade](https://discuss.elastic.co/u/whatgeorgemade)\
**Post date:** [September 24, 2021, 2:32pm UTC](https://discuss.elastic.co/t/using-multiple-hosts-in-env-var-elasticsearch-filter/285090/1 "2021-09-24T14:32:21Z")

</div>

Hi all,

I have a three node Elasticsearch cluster. I'm using Logstash to do some enrichment by pulling un-enriched documents from an index, using the `elasticsearch` filter to look up values, then output again to Elasticsearch.

The URLs for the Elasticsearch nodes are in an environment variable, which - after much reading on GitHub - I have managed to craft into a format that works for both the `input` and `output`.

Here's the environment variable defined in `/etc/default/logstash`:

```auto
ES_CLUSTER="http://ip-172-31-2-10.eu-west-2.compute.internal:9200 http://ip-172-31-2-11.eu-west-2.compute.internal:9200 http://ip-172-31-2-12.eu-west-2.compute.internal:9200"

```

This is the input block:

```auto
input {
    elasticsearch {
        hosts => "${ES_CLUSTER}"
        index => "${MGMT_INDEX}"
        schedule => "*/5 * * * *"
        tags => ["_from_elasticsearch"]
    }
}

```

This is the output block:

```auto
output {
    if [class] == "firstClass" {
        elasticsearch {
            hosts => "${ES_CLUSTER}"
            action => "create"
            index => "%{[@metadata][destIndex]}"
        }
    } else {
        elasticsearch {
            hosts => "${ES_CLUSTER}"
            document_id => "%{[idField]}"
            action => "%{[@metadata][op_type]}"
            index => "%{[@metadata][destIndex]}"
        }
    }
}

```

The filter is in the same format:

```auto
elasticsearch {
    hosts => "${ES_CLUSTER}"
    query_template => "tag_lookup.json"
    index => "${MGMT_INDEX}"
    fields => {
        "name" => "tags"
    }
    add_tag => ["ENRICH_SUCCESS_tag_lookup"]
    tag_on_failure => ["ENRICH_FAILURE", "ENRICH_FAILURE_tag_lookup"]
}

```

I can see in the logs that Logstash correctly interprets the space-delimited list of URIs for both the `input` and `output`, and establishes connections to the cluster just fine. The `filter`, however, fails:

```auto
New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["http://ip-172-31-2-10.eu-west-2.compute.internal:9200", "http://ip-172-31-2-11.eu-west-2.compute.internal:9200", "http://ip-172-31-2-12.eu-west-2.compute.internal:9200"]}
...
New ElasticSearch filter client {:hosts=>["http://ip-172-31-2-10.eu-west-2.compute.internal:9200 http://ip-172-31-2-11.eu-west-2.compute.internal:9200 http://ip-172-31-2-12.eu-west-2.compute.internal:9200"]}
Pipeline error {:pipeline_id=>"main", :exception=>#<URI::InvalidURIError: bad URI(is not URI?): http://ip-172-31-2-10.eu-west-2.compute.internal:9200 http://ip-172-31-2-11.eu-west-2.compute.internal:9200 http://ip-172-31-2-12.eu-west-2.compute.internal:9200>, ...

```

Does the Elasticsearch `filter` not support this syntax? Is there something I'm doing wrong?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 24, 2021, 2:56pm UTC](https://discuss.elastic.co/t/using-multiple-hosts-in-env-var-elasticsearch-filter/285090/2 "2021-09-24T14:56:07Z")

</div>

> [@whatgeorgemade](#):
>
> Does the Elasticsearch `filter` not support this syntax?

No. The conversion of a string that looks like an array into an array of strings is specific to [:validate =\> :uri](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/7f1099e62de50af6403fb9f1de70e1ba34534ef8/lib/logstash/plugin_mixins/elasticsearch/api_configs.rb#L149) in the option declaration. The filter expects host:port combos, [not uris](https://github.com/logstash-plugins/logstash-filter-elasticsearch/blob/8a504e96075c5143d079facffddd18dd3f1e6117/lib/logstash/filters/elasticsearch.rb#L12).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2021, 2:56pm UTC](https://discuss.elastic.co/t/using-multiple-hosts-in-env-var-elasticsearch-filter/285090/3 "2021-10-22T14:56:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
